ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Mobile Security

Antidot Android Banking Trojan Targets Users with Sophisticated Attacks

Kyle by Kyle
May 20, 2024
in Mobile Security
Reading Time: 2 mins read
A new Android banking Trojan called Antidot disguises itself as a Google Play update, using overlay attacks, keylogging, and remote access to steal credentials and data.
Share on FacebookShare on Twitter

A new banking Trojan targeting Google Android devices, dubbed “Antidot,” has emerged, disguising itself as a Google Play update. The malware displays fake Google Play update pages in multiple languages, indicating potential targets in various regions. Antidot employs overlay attacks and keylogging techniques to efficiently harvest sensitive information, such as login credentials, from unsuspecting users.

Overlay Attacks and Keylogging

Overlay attacks create fake interfaces that mimic legitimate apps, tricking users into entering their information, while keylogging captures every keystroke the user makes. This allows the malware to collect comprehensive data, including passwords and other sensitive inputs.

Malware Functionality

Rupali Parate, an Android malware researcher, explains that Antidot leverages an “Accessibility” service to function. Once installed and granted permission, it communicates with its command-and-control (C2) server to receive commands and register the device with a bot ID. The malware sends a list of installed application package names to the server, identifying target applications.

You might also like

How Hackers Still Manage to Compromise MFA

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

Upon identifying a target, the server sends an overlay injection URL (an HTML phishing page) that is displayed to the victim whenever they open the genuine application. When victims enter their credentials on this fake page, the keylogger module transmits the data to the C2 server, allowing the malware to harvest credentials.

Real-Time Control and Remote Access

Antidot uses WebSocket to maintain real-time, bidirectional communication with its C2 server, enabling the execution of commands and giving attackers significant control over infected devices. The malware can collect SMS messages, initiate USSD requests, and remotely control device features such as the camera and screen lock.

Furthermore, Antidot implements VNC (Virtual Network Computing) using MediaProjection, allowing remote control of infected devices. This capability maximizes the potential for exploitation of the victim’s financial resources and personal data, as hackers can monitor real-time activities, perform unauthorized transactions, and manipulate the device as if they were physically holding it.

Evolving Threat and Countermeasures

The emergence of Android banking Trojans poses a significant threat because they can bypass traditional security measures, exploit user trust, and gain extensive access to personal and financial information. These Trojans are growing more sophisticated through advanced obfuscation techniques, real-time C2 communication, and multilayered attack strategies.

Parate emphasizes the need for improved security measures and user awareness to combat increasingly sophisticated mobile malware. The evolution of threats like Antidot underscores the importance of implementing robust cybersecurity measures, such as strong authentication mechanisms, regular software updates, and user education on identifying and avoiding potential threats.

Tags: android
Previous Post

US Crackdown on North Korea’s Cyber Identity Theft Scheme

Next Post

Malicious Actors Exploit YouTube for Phishing, Malware, and Scams

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Discover how the BadBox botnet infects 190,000+ Android devices, compromising smart TVs and smartphones across multiple countries with dangerous malware.

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

September 16, 2024

Cybercriminals Target Mobile Users in the Czech Republic with Phishing Campaigns Leveraging Progressive Web Applications

August 20, 2024

LianSpy: New Android Spyware Targeting Russian Users

August 7, 2024

New Mandrake Android Malware Variant Evades Detection on Google Play

July 29, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.